Lucene search

K
cvelistHitachiCVELIST:CVE-2023-6457
HistoryJan 16, 2024 - 1:00 a.m.

CVE-2023-6457 File and Directory Permission Vulnerability in Hitachi Tuning Manager

2024-01-1601:00:33
CWE-276
Hitachi
www.cve.org
3
cve-2023-6457
file and directory permission
hitachi tuning manager
windows
default permissions
local users
specific files
vulnerability
version 8.8.5-04

CVSS3

6.6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

AI Score

7

Confidence

High

EPSS

0

Percentile

5.1%

Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read and write specific files.This issue affects Hitachi Tuning Manager: before 8.8.5-04.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "modules": [
      "Hitachi Tuning Manager server"
    ],
    "platforms": [
      "Windows"
    ],
    "product": "Hitachi Tuning Manager",
    "vendor": "Hitachi",
    "versions": [
      {
        "changes": [
          {
            "at": "8.8.5-04",
            "status": "unaffected"
          }
        ],
        "lessThan": "8.8.5-04",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.6

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

AI Score

7

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVELIST:CVE-2023-6457